PT-2026-31975 · Openclaw · Openclaw
Peng Zhou
·
Published
2026-03-29
·
Updated
2026-04-10
·
CVE-2026-35664
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.25
Description
OpenClaw contains an authentication bypass issue in the raw card send surface. This allows unpaired recipients to create legacy callback payloads, bypassing DM pairing restrictions and reaching callback handling without authorization. The issue was resolved by rejecting legacy raw-card command payloads, ensuring callbacks remain on the normal paired path.
Recommendations
Update to version 2026.3.25 or later.
Fix
Authentication Bypass Using an Alternate Path or Channel
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw